Skip to content

test(appsec): migrate Stripe cassettes to test-agent VCR - #20618

Open
florentinl wants to merge 2 commits into
mainfrom
florentin.labelle/stripe-agent-vcr
Open

florentinl wants to merge 2 commits into
mainfrom
florentin.labelle/stripe-agent-vcr

Conversation

@florentinl

@florentinl florentinl commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Description

Move AppSec Stripe tests from local vcrpy interception to the test agent's VCR proxy. Point both Stripe SDK entry points at the agent, register Stripe as a VCR provider, and replace 12 YAML cassettes with 13 agent cassettes. The suite now starts the test agent and no longer needs no_proxy or vcrpy.

The new cassette directory is owned by @DataDog/asm-python. Test dependency locks were regenerated for the updated suite matrix. This is test and CI work only, so no release note is needed.

Testing

  • scripts/run-tests passed all 22 Stripe tests in each of four Python 3.13 environments: latest Stripe, Stripe 11, Stripe 12, and Stripe 13 (88 test executions). The initial migration run used strict test-agent cassette replay; the final diff was rerun across all four environments.
  • scripts/lint checks passed.
  • Verified that all 13 migrated response bodies and statuses match the old recordings, that authorization headers are absent, and that recorded client_secret values remain redacted.

Risks

The test agent names cassettes using the request path, method, and body. A future Stripe SDK encoding change may require an additional cassette. The current four Stripe variants replayed the migrated recordings successfully.

Additional Notes

No issue or JIRA ticket was provided for this test maintenance change.

@florentinl florentinl added the changelog/no-changelog A changelog entry is not required for this PR. label Sep 29, 2026
@cit-pr-commenter-54b7da

Copy link
Copy Markdown

Codeowners resolved as

Resolved from the full PR diff against main using the target branch CODEOWNERS file.
CODEOWNERS team requests not listed below are not required by the current file set.

.github/CODEOWNERS                                                      @DataDog/python-guild @DataDog/apm-core-python
.gitlab/services.yml                                                    @DataDog/python-guild @DataDog/apm-core-python
.riot/requirements/1010937.txt                                          @DataDog/apm-python
.riot/requirements/105a8f8.txt                                          @DataDog/apm-python
.riot/requirements/123d1da.txt                                          @DataDog/apm-python
.riot/requirements/12f2684.txt                                          @DataDog/apm-python
.riot/requirements/13b8697.txt                                          @DataDog/apm-python
.riot/requirements/13dd1b7.txt                                          @DataDog/apm-python
.riot/requirements/1430518.txt                                          @DataDog/apm-python
.riot/requirements/1638330.txt                                          @DataDog/apm-python
.riot/requirements/1639fa1.txt                                          @DataDog/apm-python
.riot/requirements/187430f.txt                                          @DataDog/apm-python
.riot/requirements/1d3f046.txt                                          @DataDog/apm-python
.riot/requirements/24cde03.txt                                          @DataDog/apm-python
.riot/requirements/2940580.txt                                          @DataDog/apm-python
.riot/requirements/3336ae0.txt                                          @DataDog/apm-python
.riot/requirements/5178a89.txt                                          @DataDog/apm-python
.riot/requirements/5df0f73.txt                                          @DataDog/apm-python
.riot/requirements/761841a.txt                                          @DataDog/apm-python
.riot/requirements/864ec3a.txt                                          @DataDog/apm-python
.riot/requirements/9150c41.txt                                          @DataDog/apm-python
.riot/requirements/9a8f2c5.txt                                          @DataDog/apm-python
.riot/requirements/a35c878.txt                                          @DataDog/apm-python
.riot/requirements/a9de11e.txt                                          @DataDog/apm-python
.riot/requirements/c3743b3.txt                                          @DataDog/apm-python
.riot/requirements/d0edcac.txt                                          @DataDog/apm-python
docker-compose.base.yml                                                 @DataDog/python-guild
tests/appsec/integrations/stripe_tests/test_stripe.py                   @DataDog/asm-python
tests/appsec/suitespec.yml                                              @DataDog/asm-python
tests/cassettes/stripe/stripe_v1_checkout_sessions_post_76dc409b.json   @DataDog/ml-observability
tests/cassettes/stripe/stripe_v1_checkout_sessions_post_7b62036e.json   @DataDog/ml-observability
tests/cassettes/stripe/stripe_v1_checkout_sessions_post_7e73185a.json   @DataDog/ml-observability
tests/cassettes/stripe/stripe_v1_checkout_sessions_post_8f386890.json   @DataDog/ml-observability
tests/cassettes/stripe/stripe_v1_checkout_sessions_post_a3961f86.json   @DataDog/ml-observability
tests/cassettes/stripe/stripe_v1_checkout_sessions_post_bef405b6.json   @DataDog/ml-observability
tests/cassettes/stripe/stripe_v1_coupons_post_4ebe06e8.json             @DataDog/ml-observability
tests/cassettes/stripe/stripe_v1_customers_post_818020b8.json           @DataDog/ml-observability
tests/cassettes/stripe/stripe_v1_payment_intents_post_605319be.json     @DataDog/ml-observability
tests/cassettes/stripe/stripe_v1_payment_intents_post_c6a41e34.json     @DataDog/ml-observability
tests/cassettes/stripe/stripe_v1_payment_methods_pm_1SfKE5AiRiHgXZJivWogcUDl_attach_post_d8c64eb3.json  @DataDog/ml-observability
tests/cassettes/stripe/stripe_v1_payment_methods_post_2bf5af47.json     @DataDog/ml-observability
tests/cassettes/stripe/stripe_v1_promotion_codes_post_f61e528e.json     @DataDog/ml-observability

@cit-pr-commenter-54b7da

cit-pr-commenter-54b7da Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Dependency direction analysis

⚠️ Existing dependency direction violations

There are 201 dependency direction violations that already exist on the base branch and have not been changed by this PR.

Show existing violations (showing 5 of 201 highest severity)
ddtrace.internal.tracemethods -×-> ddtrace.trace  (internal-core -> product:tracing, score=132)
ddtrace.llmobs._utils -×-> ddtrace.trace  (product:llmobs -> product:tracing, score=130)
ddtrace.llmobs._integrations.langchain -×-> ddtrace.trace  (product:llmobs -> product:tracing, score=130)
ddtrace.appsec._listeners -×-> ddtrace.trace  (product:appsec -> product:tracing, score=130)
ddtrace.llmobs._integrations.llama_index -×-> ddtrace.trace  (product:llmobs -> product:tracing, score=130)

To see all violations, download the layers-base.json and layers-pr.json artifacts from this CI job and run:

uv run --script scripts/import-analysis/layers.py compare layers-base.json layers-pr.json

@datadog-official

datadog-official Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Tests

✅ All CI checks and tests passed.

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: cc94ec6 | Docs | View more details | Give us feedback!

@cit-pr-commenter-54b7da

Copy link
Copy Markdown

Circular import analysis

⚠️ Existing circular imports

There are 1 circular imports that already exist on the base branch and have not been changed by this PR.

ddtrace.errortracking._handled_exceptions.bytecode_injector -> ddtrace.errortracking._handled_exceptions.callbacks -> ddtrace.errortracking._handled_exceptions.collector -> ddtrace.errortracking._handled_exceptions.bytecode_reporting -> ddtrace.errortracking._handled_exceptions.bytecode_injector

@pr-commenter

pr-commenter Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Benchmarks

Benchmark execution time: 2026-09-29 15:38:09

Comparing candidate commit cc94ec6 in PR branch florentin.labelle/stripe-agent-vcr with baseline commit e2c6c05 in branch main.

📊 Benchmarking dashboard

Found 0 performance improvements and 8 performance regressions! Performance is the same for 606 metrics, 11 unstable metrics, 7 known flaky benchmarks, 17 flaky benchmarks without significant changes.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

scenario:httppropagationextract-empty_headers

  • 🟥 execution_time [+116.039ns; +134.293ns] or [+15.899%; +18.401%]

scenario:iastaspects-add_aspect

  • 🟥 execution_time [+9.462µs; +10.838µs] or [+11.272%; +12.911%]

scenario:iastaspects-format_map_noaspect

  • 🟥 execution_time [+101.240µs; +109.407µs] or [+28.805%; +31.129%]

scenario:iastaspectsremodule-re_expand_aspect

  • 🟥 execution_time [+79.460µs; +94.971µs] or [+12.595%; +15.054%]

scenario:msgpackencoderscenario-simple_one_span

  • 🟥 execution_time [+473.094ns; +529.917ns] or [+11.409%; +12.780%]

scenario:otelspan-start

  • 🟥 execution_time [+1.907ms; +2.752ms] or [+7.722%; +11.141%]

scenario:recursivecomputation-shallow

  • 🟥 execution_time [+51.712µs; +55.802µs] or [+7.393%; +7.977%]

scenario:span-start-finish-telemetry

  • 🟥 execution_time [+4.327ms; +4.549ms] or [+10.569%; +11.112%]

Unstable benchmarks

These benchmarks have a confidence interval too wide to call a change; treat them as noise rather than signal.

scenario:coreapiscenario-context_with_data_listeners

  • unstable execution_time [-744.285ns; +741.598ns] or [-7.159%; +7.133%]

scenario:coreapiscenario-core_dispatch_1_listener

  • unstable execution_time [-31.657ns; +47.095ns] or [-4.776%; +7.106%]

scenario:coreapiscenario-core_dispatch_50_listeners

  • unstable execution_time [-1940.684ns; +1901.933ns] or [-9.746%; +9.551%]

scenario:coreapiscenario-core_dispatch_exception_listeners

  • unstable execution_time [-2285.937ns; +1774.741ns] or [-11.651%; +9.045%]

scenario:coreapiscenario-core_dispatch_listeners

  • unstable execution_time [-397.348ns; +367.200ns] or [-9.323%; +8.616%]

scenario:coreapiscenario-core_dispatch_no_args_listeners

  • unstable execution_time [-236.641ns; +223.291ns] or [-8.864%; +8.364%]

scenario:coreapiscenario-core_dispatch_with_results_1_listener

  • unstable execution_time [-102.210ns; +83.079ns] or [-7.464%; +6.067%]

scenario:coreapiscenario-core_dispatch_with_results_50_listeners

  • unstable execution_time [-4536.331ns; +4752.517ns] or [-9.444%; +9.894%]

scenario:coreapiscenario-core_dispatch_with_results_listeners

  • unstable execution_time [-797.145ns; +1110.078ns] or [-7.881%; +10.974%]

scenario:flasksqli-iast-enabled

  • unstable execution_time [-79.712µs; +257.619µs] or [-4.269%; +13.798%]

scenario:packagesupdateimporteddependencies-import_many_stdlib_cached

  • unstable execution_time [-53.202µs; +56.706µs] or [-9.373%; +9.990%]

Known flaky benchmarks

These benchmarks are marked as flaky and will not trigger a failure. Modify FLAKY_BENCHMARKS_REGEX to control which benchmarks are marked as flaky.

scenario:httppropagationinject-ids_only

  • 🟥 execution_time [+2.938µs; +3.025µs] or [+20.892%; +21.512%]

scenario:iastaspects-title_noaspect

  • 🟥 execution_time [+34.790µs; +39.215µs] or [+17.194%; +19.381%]

scenario:iastaspectsospath-ospathbasename_aspect

  • 🟥 execution_time [+142.256µs; +146.767µs] or [+37.512%; +38.702%]

scenario:iastaspectssplit-rsplit_aspect

  • 🟥 execution_time [+30.834µs; +34.756µs] or [+19.702%; +22.208%]

scenario:span-start

  • 🟥 execution_time [+1.228ms; +1.674ms] or [+9.779%; +13.337%]

scenario:telemetryaddmetric-1-count-metric-1-times

  • 🟥 execution_time [+234.595ns; +279.137ns] or [+12.269%; +14.598%]

scenario:tracer-small

  • 🟥 execution_time [+43.302µs; +44.782µs] or [+17.652%; +18.256%]

Known flaky benchmarks without significant changes:

  • scenario:errortrackingflasksqli-baseline
  • scenario:flasksimple-iast-get
  • scenario:iastaspects-casefold_aspect
  • scenario:iastaspects-casefold_noaspect
  • scenario:iastaspects-index_aspect
  • scenario:iastaspects-ljust_noaspect
  • scenario:iastaspects-lower_aspect
  • scenario:iastaspects-replace_aspect
  • scenario:iastaspects-rstrip_aspect
  • scenario:iastaspects-swapcase_aspect
  • scenario:iastaspects-translate_aspect
  • scenario:iastaspects-translate_noaspect
  • scenario:iastaspects-upper_noaspect
  • scenario:packagespackageforrootmodulemapping-cache_off
  • scenario:packagespackageforrootmodulemapping-cache_on
  • scenario:sethttpmeta-all-enabled
  • scenario:telemetryaddmetric-record-100-metrics

@florentinl
florentinl marked this pull request as ready for review September 29, 2026 12:39
@florentinl
florentinl requested review from a team as code owners September 29, 2026 12:39
@florentinl
florentinl requested review from avara1986 and emmettbutler and removed request for a team September 29, 2026 12:39
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T12:43:43.586943Z f00c2d9 Draft marked ready
🔒 Security Review ✅ Completed 2026-09-29T12:44:14.420852Z f00c2d9 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

changelog/no-changelog A changelog entry is not required for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants